Case file · anonymized · Malvertising · consumer threat intel

86 paid ads. 90 days. One family member.

Meta was paid to deliver 86 Facebook, Instagram, and Messenger ads to one family member over three months. Two landed on fake-antivirus browser lockers. Eight promoted manufactured medical-anxiety domains. Cross-referencing the campaign IDs shows that at least two of the fake landing pages were run by the same operator under different business names. We pulled the receipts.

July 16, 2026 · 8 min read · worked by the principal

86Meta-served paid ads delivered to one browser in 90 days

Someone in our family called us in a panic because a full-screen popup on their laptop had told them their computer was infected and to call “Windows Support” at a toll-free number. Same scam we’ve seen a hundred times. Kill the tab, check for remote-access installers, done in under an hour.

But this time we didn’t stop there. We pulled ninety days of browser history off the machine and ran it through an ad-click analyzer we’ve been building. The result is the most concrete answer we’ve ever had to the question who is actually paying for this to happen?

The answer is Meta. Specifically. By dollar amount. With the campaign IDs in the URL parameters to prove it.

What the browser was seeing

Over the ninety-day window, this one browser recorded 18,156 visits. Of those, 131 were paid-ad or click-tracked links — URLs with an fbclid, a gclid, an msclkid, an l.facebook.com/l.php wrapper, or an equivalent tracking signal that only appears when the click originated inside a paid ad or a click-tracked link.

86
Meta paid + wrapper
24
Google paid
12
Bing paid
9
Email marketing

Two-thirds of the paid-ad exposure this browser received was Meta.

What the ads led to

Once the analyzer classifies each landing page — by TLD, by URL pattern, by brand impersonation, by category keywords — the pattern of what was being served becomes hard to look away from.

  • 13 ads — single-condition medical-anxiety landings. Domains like screenheartvalvedisease.com and treatheartvalvefailure.com. Dedicated single-purpose websites, each targeting one scary medical condition, each buying paid search and social placement against elder-adjacent audiences.
  • 10 ads — elder-financial pitches. Reverse-mortgage refinance, annuity offers, dedicated marketing landing pages for “asset” and “wealth” brands. Meta paid to place these six separate times to the same person on the same subdomain over ten days.
  • 9 ads — background-check subscription traps. Domains like classmates.com and peoplelooker.com. Users click through what looks like a $1 record lookup and are enrolled in $20-30 monthly auto-billing they will forget about for a year.
  • 11 ads — foreign clickbait content farms. Turkish-language and Chinese-language content mills accepting Meta ad spend to drive traffic to pages full of programmatic display ads. This is how the middle of the click-monetization ecosystem gets funded.
  • 4 ads — throwaway ad-farm rotators. URLs like rmn.lgnrd22.com — randomized-subdomain destinations that rotate weekly to stay under abuse-reporting thresholds.
  • 3 ads — charity / pet-rescue scam pattern. Pages soliciting donations for “puppies in need close by,” served through Meta’s ad system.
  • 2 ads — fake antivirus browser lockers. The one that triggered the call for help (a .cfd throwaway domain), plus an earlier one from six weeks prior that was hosted on Microsoft’s own Azure Blob Storage — viruswarning0603usprg914.z13.web.core.windows.net. Same family member. Two separate fake-AV incidents in six weeks. Both delivered via paid ads. One using Microsoft’s own cloud infrastructure to host the scam.
  • 2 ads — classic subscription trap. A v2.allfreetrial.com URL served twice by Meta in the same ninety-second window — the same offer, hit twice, from what were probably two separate placements of the same campaign.

The receipt

Using industry-standard rates for elder-adjacent audience targeting (Meta CPC around $2.20 in the US financial/health verticals, CPM around $12 for the same audience, thirtyish impressions per click on that demographic) we can estimate what the platforms plausibly collected in exchange for delivering the above:

PlatformClicks observedEst. click revenueEst. impression revenueEst. total
Meta (paid + wrapper)86$189.20$30.96$220.16
Google (paid + display)24$79.20$10.08$89.28
Bing12$19.20$3.24$22.44
Total ad-platform revenue attributable to one browser, 90 days$331.88

These are conservative midpoints. The real numbers depend on the advertiser account and auction dynamics that only Meta and Google see. But the order of magnitude is the point.

The single most-served advertiser (six paid Meta placements against the same asset-management landing page over ten days) cost their advertiser approximately $13 for the observed clicks alone. Meta got paid the same amount whether the click generated a real service or an elder-financial pitch. Meta’s ad-serving system does not distinguish.

The smoking gun

Facebook click IDs and UTM campaign parameters follow the click from ad-service through to the landing-page URL. This means you can cross-reference the same campaign ID appearing across different landing pages — and when you do, you find that a single operator is running multiple fake-business fronts.

Two examples that survived the analyzer’s clustering pass:

Meta campaign ID 120247003249040063 appears on two different destinations: the June 3rd fake-antivirus browser locker (viruswarning0603usprg914.z13.web.core.windows.net) and a generic-name landing page roshri.com. Same Meta ad campaign. Two different scam destinations. One operator running multiple fronts through the same paid budget.

Meta campaign ID 120244824961160618 appears on two more: zhongyuedz.com (Chinese-language throwaway) and haoz-c3eph0f4f4bzbtc0.z02.azurefd.net — another Microsoft Azure endpoint, this time Azure Front Door being used to launder the scam infrastructure behind a Microsoft-owned hostname.

These clusters are provable from the URLs alone. No inside access to the ad accounts is needed. The receipts are in the click parameters your browser stores every time you follow a paid link.

What Meta’s policy says vs. what the ads were

Meta’s advertising standards explicitly prohibit ads that promote fraud or deception, misrepresent products or services, or exploit users’ anxieties about health conditions. The standards also prohibit ads that lead to landing pages that impersonate authentic websites or that use surprise-billing dark patterns.

Every ad category enumerated above — fake antivirus, medical-anxiety single-condition landing, subscription trap, background-check auto-bill, throwaway domain rotator — is a documented, policy-forbidden category. Meta’s enforcement is supposed to catch these before they run. In this one browser’s ninety-day window, enforcement caught none of them.

The problem is not that a bad ad slipped through. The problem is that eighty-six of them didn’t.

The tool we used

We built a small, single-file Python analyzer that reads Chrome, Edge, or Firefox browser history (from a live profile or a forensic export), filters to just the ad-click URLs, resolves the landing destination after unwrapping l.facebook.com-style redirects, classifies the landing by category and TLD, extracts every campaign identifier, and emits a self-contained HTML report with the money math and the cross-domain UTM clusters called out at the top.

Everything in this post came from that report. Every claim above is anchored to specific timestamps, specific campaign IDs, and specific URLs in the browser’s own local history file.

What you can do right now

Two things. Free. Same day.

  1. Look at a family member’s Facebook feed the next time you’re on their laptop. Scroll for three minutes. Count the ads. Count the ones that use anxiety words in their headline (heart, kidney, bladder, memory, sweepstakes, benefits, medicare, gift card). If it’s more than a couple, you have a targeted-elder profile in front of you.
  2. Report every scam ad you can identify to Meta’s ad-abuse form. The report needs the ad in question and, ideally, the campaign ID (visible in Meta’s Ad Library if you have the creative ID). Meta’s enforcement responds to volume more than to individual reports.

If you want the actual receipts — the money math, the campaign IDs, the cross-domain clusters, the timeline — on a family member’s laptop, we can run the same analysis. It takes one browser-history export and about ninety seconds of processing. Ask us.


This case has been anonymized per our marketing policy. The 86, 131, 18,156, and 90-day figures are exact. The specific domain names and campaign IDs above are unaltered because they are evidence, not private information — anyone running the same analysis on the same browser would surface the identical set. The family member’s identity, geography, age, relationship, and any personally identifying detail have been generalized.

Seeing this pattern in your tenant? The person who worked this case answers the email. Originally published on the Envyously blog.